<?xml version="1.0" encoding="utf-8"?><!-- generator="wordpress/2.0.5" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: On Compliance</title>
	<link>http://thurston.halfcat.org/blog/2008/06/19/on-compliance/</link>
	<description>We are the people your IT department warned you about</description>
	<pubDate>Fri, 12 Mar 2010 10:38:30 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.5</generator>

	<item>
		<title>by: Chandler Howell</title>
		<link>http://thurston.halfcat.org/blog/2008/06/19/on-compliance/#comment-247004</link>
		<pubDate>Fri, 20 Jun 2008 17:21:16 +0000</pubDate>
		<guid>http://thurston.halfcat.org/blog/2008/06/19/on-compliance/#comment-247004</guid>
					<description>no worries.  The criticism would be of the delivery, not the content, and I'll be the first one to agree that sometimes, it just sneaks out.</description>
		<content:encoded><![CDATA[<p>no worries.  The criticism would be of the delivery, not the content, and I&#8217;ll be the first one to agree that sometimes, it just sneaks out.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Alex</title>
		<link>http://thurston.halfcat.org/blog/2008/06/19/on-compliance/#comment-246971</link>
		<pubDate>Fri, 20 Jun 2008 15:00:11 +0000</pubDate>
		<guid>http://thurston.halfcat.org/blog/2008/06/19/on-compliance/#comment-246971</guid>
					<description>Yeah, it just hit me wrong.  I get too much coffee, I'm in a bad mood, read something that I'm passionate about and BOOM I write something like that :)

Apologies for the dogmatic comments...</description>
		<content:encoded><![CDATA[<p>Yeah, it just hit me wrong.  I get too much coffee, I&#8217;m in a bad mood, read something that I&#8217;m passionate about and BOOM I write something like that :)</p>
<p>Apologies for the dogmatic comments&#8230;
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Chandler Howell</title>
		<link>http://thurston.halfcat.org/blog/2008/06/19/on-compliance/#comment-246790</link>
		<pubDate>Thu, 19 Jun 2008 19:52:55 +0000</pubDate>
		<guid>http://thurston.halfcat.org/blog/2008/06/19/on-compliance/#comment-246790</guid>
					<description>It would appear that some would think I'm too kind in responding to my critics... ;-)</description>
		<content:encoded><![CDATA[<p>It would appear that some would think I&#8217;m too kind in responding to my critics&#8230; ;-)
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Alex</title>
		<link>http://thurston.halfcat.org/blog/2008/06/19/on-compliance/#comment-246762</link>
		<pubDate>Thu, 19 Jun 2008 18:49:21 +0000</pubDate>
		<guid>http://thurston.halfcat.org/blog/2008/06/19/on-compliance/#comment-246762</guid>
					<description>Not trying to be antagonistic or snarky here,  but:

"I still want to know what are the baselines, the metrics, and the guiding standards for Information Risk Management. IRM points to directly the security standards and baselines like ISO 27001."

NO.

No, no, no, no, no, no, no, no, no.  no.

Not even close. 

"Baselines" like ISO 27001 or any other ISMS have very little to do with actual "management by and of, risk".  In other words:

1.)  An ISMS is not an IRMS (Information Risk Management System - if such a thing exists - and please don't point me to SABSA as an example).

2.)  Much of what various ISMS frameworks call "Risk Management" is actually a heightened vulnerability management cycle.

3.)  Managing discrete tactical issues is not, can not, be the sum total of what management by and of, risk, *is*.

Finally, the metrics of risk have to do with *expressing the value* of being at some state of "secure" - and not just the measurement of "how secure" itself.</description>
		<content:encoded><![CDATA[<p>Not trying to be antagonistic or snarky here,  but:</p>
<p>&#8220;I still want to know what are the baselines, the metrics, and the guiding standards for Information Risk Management. IRM points to directly the security standards and baselines like ISO 27001.&#8221;</p>
<p>NO.</p>
<p>No, no, no, no, no, no, no, no, no.  no.</p>
<p>Not even close. </p>
<p>&#8220;Baselines&#8221; like ISO 27001 or any other ISMS have very little to do with actual &#8220;management by and of, risk&#8221;.  In other words:</p>
<p>1.)  An ISMS is not an IRMS (Information Risk Management System - if such a thing exists - and please don&#8217;t point me to SABSA as an example).</p>
<p>2.)  Much of what various ISMS frameworks call &#8220;Risk Management&#8221; is actually a heightened vulnerability management cycle.</p>
<p>3.)  Managing discrete tactical issues is not, can not, be the sum total of what management by and of, risk, *is*.</p>
<p>Finally, the metrics of risk have to do with *expressing the value* of being at some state of &#8220;secure&#8221; - and not just the measurement of &#8220;how secure&#8221; itself.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
